CWE-79
CVEs classified under CWE-79, newest first.
2125 CVEsRSS
CVE-2026-55779Medium· 5.4Silverstripe Versioned provides versioning for Silverstripe models
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Ti…
CVE-2026-55696Medium· 4.3PrivateBin is an online pastebin where the server has zero knowledge of pasted data
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobU…
CVE-2026-55566Medium· 4.3Yamcs is a mission control framework
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component…
CVE-2026-55464Medium· 5.4Snipe-IT vulnerable to stored XSS via Markdown custom field
Snipe-IT vulnerable to stored XSS via Markdown custom field
CVE-2026-55549Medium· 6.5PoCYamcs is a mission control framework
Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping b…
CVE-2026-81731Medium· 5.4Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description
Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with "ignore_xss_filter": 1 in frappe/desk/doctype/workspace_link/wor…
CVE-2026-53579NoneTrilium is an open-source hierarchical note-taking application
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book note type, whose content is stored with…
CVE-2026-53578NoneTrilium is an open-source hierarchical note-taking application
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is sto…
CVE-2026-59316High· 8.2Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is…
CVE-2026-48996NoneTrilium is an open-source hierarchical note-taking application
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view interpolates a marker note's title into …
CVE-2026-54720Medium· 5.4Silverstripe Framework: Possible XSS attack through media embed
Silverstripe Framework: Possible XSS attack through media embed
CVE-2026-80426High· 7.1FiftyOne renders a dataset field's description as markup
FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React's dangerouslySetInnerHTML, and no la…
CVE-2026-47666High· 7.6Penpot is an open-source design and prototyping platform
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and…
CVE-2026-47665High· 8.7Penpot is an open-source design and prototyping platform
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page w…
GHSA-7w8c-qgxg-m7jxHigh· 7.1LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
CVE-2026-44701Low· 3.5OpenSTAManager has HTML Injection in modules/utenti/edit.php
OpenSTAManager has HTML Injection in modules/utenti/edit.php
CVE-2026-54606HighSunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and proc…
CVE-2026-45694Medium· 5.4LibreNMS is a network monitoring system
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected…
CVE-2026-32257High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission …
CVE-2026-32258High· 8.1Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are c…
CVE-2026-26211Medium· 4.8PoCEkushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding
Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element…
CVE-2026-77996NoneJoomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
CVE-2026-56704Medium· 6.1Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of th…
CVE-2026-55596High· 8.7Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
CVE-2026-65053Medium· 6.1Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it
Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of the data part with IMP_Contents::getPar…
CVE-2026-10618Medium· 5.4Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them
Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a b…
CVE-2026-76837Medium· 6.4Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding
Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer in web-frontend/modules/core/editor/mention.js bu…
CVE-2026-30864High· 8.9Combodo iTop is a web-based IT service management tool
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
CVE-2022-30983Medium· 6.1A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
CVE-2026-71503Medium· 6.1Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no …
Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no …